Back to jobs
New

Principal Linux Security Engineer

Remote

CIQ OVERVIEW

CIQ builds the enterprise infrastructure that powers the world's most demanding workloads. From the operating system layer through AI infrastructure, high-performance computing, and cloud-native orchestration, CIQ delivers the speed, security, scalability, and sovereignty that major enterprises, government agencies, and research institutions depend on.

CIQ is the founding support and services partner of Rocky Linux and the developer of the RLC Pro family of Enterprise Linux distributions, Fuzzball workload orchestration, Warewulf Pro cluster provisioning, and Ascender Pro automation. Our customers include some of the largest and most technically sophisticated organizations in the world, working across HPC, AI/ML, defense, and regulated industries.

We are a company of builders, operators, and open source practitioners. If you want to do work that matters, at a company that is genuinely changing how enterprise infrastructure gets built and run, we want to talk.

POSITION SUMMARY 

This isn't a traditional job description. It describes the specific person we're looking for: an engineer who understands the Linux operating system from a security perspective.

What does that mean in practice? Here is what we need from this role:

  • How security errata works in an operating system (CSAF, VEX, Advisories) and how to create them and use them in various aspects of the systems, from updateinfo in repos to a security feed for security scanners to ingest. 
  • Compliance on an operating system - Building out STIG and DIS profiles. Understanding how to improve OpenSCAP and building Ansible scripts to apply the security profiles, not just applying scripts that someone else built.
  • Proactive security in an operating system, like build flags, LKRG, SELinux. How to really secure the OS in a way that also allows it to be usable. Not hooking it up to the internet is not an acceptable security answer.
  • How to build tools to make the above happen faster and interact with AI to speed up development, testing, and release. 
  • CVE scoring - How they are scored and what that means.  It doesn’t mean that you know how to look up a score in NIST, but it means you have used the CVSS calculator and you know why it is scored a 7.8 vs. a 5.5
  • CVE affectedness - You understand how to determine if a piece of software is affected by a CVE and how different aspects of build and configuration change the affectedness. 

Is This Role Right for You?

If the requirements above don't resonate with your experience, this position is likely not the right fit. If you meet most of them, we'd like to hear from you. We're looking for candidates who are genuinely engaged with this work, so we ask that automated or mass applications be avoided.

EDUCATION AND EXPERIENCE 

  • Proven work experience in Security and/or Linux Engineering with a focus on the Linux OS.
  • At least 4 years of experience doing security in Linux and at least 2 years of experience building Linux Packages

BENEFITS

  • Medical, dental, and vision insurance.

  • Flexible paid time off.

  • Employee stock options.

  • Remote work; no travel required for most positions.

 

Create a Job Alert

Interested in building your career at CIQ? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...
Select...

U.S. Standard Demographic Questions

We invite applicants to share their demographic background. If you choose to complete this survey, your responses may be used to identify areas of improvement in our hiring process.
Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in CIQ’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...


Application Disclosure

 

Use of Recruiting Technology

 

As part of our recruiting process, CIQ uses technology tools within our applicant tracking system to assist recruiters in reviewing and organizing applications. These tools may help identify candidates whose qualifications align with job-related criteria, detect potential fraud or spam activity, and support recruiting workflow efficiencies.

 

These tools do not make hiring decisions. All employment decisions are made by CIQ personnel based on a holistic review of candidate qualifications and other job-related factors.

 

Candidates who require an accommodation, alternative application process, or other assistance during the recruiting process should contact CIQ Human Resources at hr@ciq.com.


 


Learn more